Files
amethyst/commonsUI
Claude 64da9cb9c3 fix(health): make the permission rationale argue the use case we declared
Google rejected the Health Connect declaration a second time with the same
code as the first: "Use of permission is not a permitted/valid use case ...
or potentially engages in a prohibited use."

The declaration was not what failed. The My Fitness pivot rewrote
docs/health-connect-play-declaration.md and PRIVACY.md but never touched the
strings behind HealthConnectRationaleScreen - the screen the declaration
points the reviewer at, and the one Health Connect itself opens for
ACTION_SHOW_PERMISSIONS_RATIONALE. It still carried the rejected first
submission verbatim: "Amethyst reads finished workouts so it can pre-fill a
workout post for you ... so the people who follow you can see what you did."
That is the prohibited "publicly displaying or socially sharing sensitive
data", presented in-app as the official justification for the permission.

Three further contradictions on the same screen: every per-permission bullet
justified the data type by what it puts in the post rather than by the
statistic My Fitness renders; it claimed a 7-day window and "only while the
Workouts composer is open" against the 28 days and My Fitness the declaration
claims (WorkoutStats.WINDOW_DAYS = 28 drives the dashboard, LOOKBACK_DAYS = 7
only ever drove the composer); and My Fitness was not named anywhere on it.
The composer's permission card had the same problem - it was titled "Share
your workouts".

Both surfaces now tie every permission to a statistic the dashboard shows the
user, state the 4-week window and both screens that read, name My Fitness, and
describe publishing only under "What Amethyst does not do" as an optional,
per-item, explicitly-confirmed action.

The translated copies of the 13 changed strings are deleted so every locale
falls back to the corrected English until Crowdin re-translates, rather than
keeping the rejected wording live in 7 languages.

Also records the root cause in the declaration doc, and fixes the reviewer
walkthrough to log a workout before opening the dashboard - a review device's
Health Connect database is empty, and an empty dashboard demonstrates none of
the statistics these permissions serve.

Verified: the merged playRelease manifest declares exactly the 7
android.permission.health.* entries and no ACTIVITY_RECOGNITION or
BODY_SENSORS leaked in from any dependency, so this was never a
manifest/declaration mismatch.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TPShPiTfg16yesupcLgyqf
2026-09-21 22:11:23 +00:00
..